SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

Redefining AI Sovereignty / Thoughts on Sovereignty as 'Options' Read Through CSD


0 Introduction

The term 'AI sovereignty' has rapidly gained acceptance overseas over the past six months. However, while this term is convenient, it is also dangerous. It is convenient because it allows disparate issues—semiconductors, cloud computing, foundation models, data, standardization, and regulation—to be bundled under the grand banner of sovereignty. It is dangerous because that grand banner often acts as a license to omit substantive discussion.

As a recent example, the report 'Sovereignty in the Age of AI,' published in January 2026 by the Tony Blair Institute for Global Change (hereinafter referred to as TBI), addresses this danger head-on. It clearly emphasizes that while sovereignty is important, the goal is not isolation or domestic ownership of every layer of AI. It then presents a blueprint for translating the question of who shapes values and governs access into the language of policy practice, as AI adoption accelerates and economic, geopolitical, and public service delivery models are restructured.

In this article, I will organize the role of law by using the TBI report's central proposition—the redefinition of sovereignty as strategic agency and options rather than self-sufficiency—as a guide. The goal is simple: to prevent sovereignty discourse from devolving into a narrative that merely stimulates national pride or anxiety, and instead connect it to concrete institutional design regarding which layers should be subject to what degree of control, steering, or dependence.

1 The Location of the Problem: Excessive Compression of the Term 'Sovereignty'

In international law and constitutional law, sovereignty is a core concept linked to ultimate decision-making power. However, sovereignty as discussed in the context of AI often circulates as a catchphrase for policy packages while leaving its semantics ambiguous. For example, there are instances where creating a domestic LLM is immediately equated with the establishment of sovereignty. Yet, even if a model is localized, if computing resources depend on foreign clouds, or if data, evaluation infrastructure, and operational talent are lacking, governance capacity does not effectively increase. Conversely, even if a model is foreign-made, it is sometimes possible to secure operational options and resilience through the design of procurement, contracts, audits, and exit strategies.

This type of confusion is further amplified when technology companies market 'sovereignty as a service.' As the TBI report points out, localized clouds, compliance wrappers, and the like may provide control on the surface, but they can effectively deepen dependence. As long as one attempts to measure sovereignty by nominal ownership or location, it is easy to fall into this trap.

The biggest problem occurring here is the extreme concentration of resources in the AI ecosystem and the resulting inevitable interdependence. The development and deployment of frontier AI require cutting-edge semiconductors, hyperscale data centers, and vast amounts of clean energy. According to TBI's analysis, the United States and China control over 90% of the world's AI data center capacity. Furthermore, the location of AI computing resources is estimated at approximately 75% in the U.S., 15% in China, and about 10% in the rest of the world, primarily in Europe; only 32 countries possess AI-specialized data centers, while approximately 160 countries are organized as being dependent on foreign infrastructure.

Therefore, there are two locations of the problem. First, the units used when discussing sovereignty are too coarse. Second, the tools to realize sovereignty have not been concretized at the level of law, contracts, and institutions. The interest of the TBI report lies precisely in breaking down this coarseness.

2 Key Points of the TBI Report: Self-Sufficiency is Not Sovereignty

The TBI report's argument is, in a sense, blunt. The development and operation of frontier AI require capital, energy, talent, data, semiconductors, and hyperscale data centers, and as a consequence of economies of scale, their supply is concentrated in a small number of countries and companies.

In the face of this reality, a vision of sovereignty that involves doing everything in-house is, for many countries, impossible in terms of both cost and time. Moreover, what is important is not just that it is impossible, but that this vision of sovereignty misunderstands the essence of sovereignty. The TBI report defines sovereignty not as complete independence from others, but as the ability to act strategically with agency and options in an irreversibly interdependent world. In the context of AI, the core of sovereignty is shaping how AI is used domestically, having realistic options regarding infrastructure, models, and partners, and maintaining the flexibility to adapt as technology changes.

What is important here is the rejection of the simple schema that dependence equals evil. The TBI report states that avoiding access to frontier AI can itself become a significant threat to sovereignty. Countries that cannot use the best systems will depend on those that can, and will relatively lose their capacity for defense, growth, and public service delivery. In other words, protectionism and isolation may not protect sovereignty, but rather weaken it.

3 The AI Stack and CSD: Having Control, Steering, and Dependence by Layer

The TBI report presents the AI stack as the unit for discussing sovereignty. It consists of seven layers: computing infrastructure, energy, data, models, applications, talent/skills, and governance. The point here is to fix the obvious fact that models are not the only battlefield as a unit of institutional design. Even if one is enthusiastic about domesticating models, other layers constrain the overall options, such as data centers not running due to energy constraints, talent leaving, or regulations losing credibility and causing the market to shrink.

Based on this AI stack, the TBI report presents Control, Steer, and Depend (hereinafter referred to as CSD) as a framework for organizing a nation's sovereignty posture.

Control is a posture where a nation determines that it cannot entrust critical systems to external parties and secures ownership, legal authority, and operational command. However, Control does not mean nationalization or a closed economy. The focus is on having a fallback for mission-critical areas, for example, by ensuring that services cannot be unilaterally withdrawn and that domestic legal jurisdiction is secured.

Steer is a posture of guiding outcomes through regulation, procurement, standardization, investment incentives, and public-private partnerships without involving ownership or direct control. The effectiveness of Steer depends on the credibility of the system, market power, and international influence. Without enforcement capacity, steering devolves into a symbolic gesture.

Depend is a posture that assumes dependence on external entities. However, what is important here is that Depend is not monolithic. The TBI report distinguishes between 'maker dependence' (negotiated dependence) and 'taker dependence' (passive dependence). The former actively engages in dependence through joint development, technology transfer, etc., whereas the latter involves adopting everything via APIs or licenses and lacks the capacity for auditing, substitution, or modification, thus carrying a high risk of vendor lock-in.

The advantage of CSD is that it allows sovereignty to be depicted not as a ladder of 'more sovereign' or 'less sovereign,' but as a combination by layer. No country can achieve Control in all seven layers. Rather, the question is the design of the configuration: in which layers is Control essential, in which layers is Steer sufficient, and in which layers should one assume Depend while moving toward becoming a 'maker'.

4 Where Does Law Fit In? Increasing Sovereignty as a Set of Choices

Translating CSD into the language of law, the core of sovereignty can be rephrased as a set of choices and the institutional capacity to actually exercise those choices. The role that law plays here boils down to three points: creating choices, protecting choices, and enabling the exercise of choices.

First, creating choices is a design that enables exit, switching, and substitution while assuming dependencies. Specifically, typical examples include audit rights in public procurement and outsourcing contracts, duties of explanation, change management, data/log portability, model substitutability (portability), and service continuity clauses in emergencies. These are techniques of law and contract that push 'Depend' from 'taker' to 'maker'.

Second, protecting choices means ensuring minimum fallback capabilities in mission-critical areas. TBI also states that while a certain amount of domestic computing resources is necessary for resilience in areas such as healthcare and national security, frontier-scale replication is unnecessary for many countries. This minimum line-drawing is a matter of legal system theory as much as it is a matter of technology theory. This is because determining which areas to designate as critical infrastructure, what level of continuity and availability to require, and who bears the costs are typically domains of law.

Third, enabling the exercise of choices means guaranteeing as an institution the state capacity that makes 'Steer' possible—namely, regulatory credibility, enforcement capability, specialized human resources, and international negotiation power. Even if AI regulation is beautiful on paper, 'Steer' will not materialize without implementation and operation. It is in this context that we can understand why the EU AI Act has a system linked not just to simple prohibitions, but to risk classification, conformity assessment, supervisory structures, and standardization. Also, the movement to refer to corporate risk management frameworks (such as the NIST AI RMF) as implementation units for governance cannot be ignored as long as law focuses on process regulation.

In short, discussing AI sovereignty is ultimately about discussing the infrastructure of governance. Before questioning the nationality of a model, it is necessary to question the implementation of governance, including contracts, procurement, standards, supervision, human resources, and even energy planning.

5 Implications for Corporate AI Personnel: National Sovereignty is Determined by Corporate Procurement Design

For corporate AI personnel, AI sovereignty may at first glance appear to be a matter for the state. However, in reality, the state's CSD configuration is embodied as a collection of corporate procurement and operations. When the state shapes the market through 'Steer,' that kick comes down to companies not only as regulations but also as public procurement, subsidies, standards, evaluation systems, guidelines, and so on. If companies cannot perform procurement and operations that conform to those systems, the state's 'Steer' will spin its wheels.

As for practical work on the corporate side, it is first necessary to break down the company's own AI stack and visualize where 'taker' dependency exists. This includes questions such as: Are you dependent on model APIs? Is your data infrastructure locked into a specific cloud? Is the evaluation/audit mechanism a black box provided by a vendor? Is the staff's skill dependent on external consultants?

Next, if dependency is unavoidable, make the dependency negotiable. Specifically, this involves embedding into contracts: audit/verification authority (including third-party evaluation), handling of data and logs (restrictions on use for training, portability, deletion), notification and impact assessment when models or services change, cooperation obligations during security incidents, and transition support upon termination. These are modest, but from the perspective that sovereignty equals choices, they are often more effective than flashy domestic production.

Finally, there is the implementation of governance. The NIST AI RMF and its Generative AI Profile are useful as frameworks for connecting AI risks to an organization's decision-making process. However, misunderstandings are prone to occur here as well. A framework is not an indulgence; it is the starting point for accountability. The question is whether the adopted framework has been translated into actual operations (evaluation, improvement, recording, explanation).

6 Random Thoughts

The word 'sovereignty' is easily waved as a flag. However, what is needed in the age of AI is not a flag, but a handrail. In other words, it is to find places where one might fall (concentration of dependency, energy constraints, hollowing out of human resources, hollowed-out regulations) and install handrails (fallback, exit, audit, standards, institutional capacity) there.

The greatest takeaway from the TBI report is that it stripped sovereignty away from complete control and redefined it as strategic resilience. That redefinition is convenient for law. This is because law is inherently a technique for implementing freedom not as an abstract ideal, but as a system that supports choices.

Discourse on AI sovereignty often places technology outside the state and attempts to defend against it as something coming from the outside. However, AI has already entered the interior of governance. It is permeating the provision of public services, administrative decision-making, and the depths of corporate business processes. That is precisely why the discussion of sovereignty should question the presence of governance capability rather than the presence of domestic models. Sovereignty is not something you create; it is something you continue to operate.

Reference Materials
Tony Blair Institute for Global Change, "Sovereignty in the Age of AI: Strategic Choices, Structural Dependencies and the Long Game Ahead" (January 2026)
https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies
https://assets.ctfassets.net/2vn29h6gqv4j/4I6kcG9I5VbqgeivQOaZV6/1e0e19159b1e44317a2edb10904e8226/TBI_2026_Sovereignty_in_the_Age_of_AI.pdf
(Accessed January 26, 2026)
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 2024/1689, 12.7.2024
https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
(Accessed January 26, 2026)
National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework (AI RMF 1.0)" (January 2023)
https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
(Accessed January 26, 2026)
National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" (July 2024)
https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
(Accessed January 26, 2026)

(Magazine) "AI and Law - Random Thoughts"

*See below for the table of contents

note General Terms of Service Article 3, Paragraph 2, First Sentence
3.2 The copyright of digital content produced by the creator belongs to the creator.

いいなと思ったら応援しよう!